Threat Vulnerability Lead

Glocomms
London, UK
2 days ago
Apply on www.collegerecruiter.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Working hours
Regular working hours

Tech stack

Application Programming Interfaces (APIs) Cyber Security System Configuration Python (Programming Language) Open Web Application Security Windows PowerShell Security Information and Event Management Systems Integration Software Vulnerability Management Mitre Att&ck QRadar Cyber Threat Analysis
+6 more
Microsoft Sentinel Cortex XSOAR Platform Splunk Qualys Security Orchestration, Automation & Response Servicenow

Job description

  • Serve as the primary owner and administrator of the organisation’s ThreatConnect Threat Intelligence Platform (TIP), ensuring effective integration, maintenance, and optimisation.
  • Develop and maintain ThreatConnect workflows, playbooks, dashboards, and intelligence-sharing processes to improve threat visibility and response capabilities.
  • Integrate ThreatConnect with SIEM, SOAR, incident response, and vulnerability management platforms to automate intelligence sharing, enrichment, prioritisation, and reporting.
  • Leverage ThreatConnect to manage threat feeds, indicators of compromise (IOCs), threat actor profiles, campaigns, and TTPs aligned to the MITRE ATT&CK framework.
  • Continuously improve threat intelligence ingestion, enrichment, correlation, reporting, and operationalisation through ThreatConnect automation and orchestration capabilities.

Requirements

  • At least 10 years of experience in cybersecurity engineering or operations roles, with at least 5 years of hands-on experience in Threat Intelligence and Vulnerability Management.
  • Strong experience across the threat intelligence lifecycle, including collection, analysis, enrichment, correlation, and dissemination of actionable intelligence.
  • Hands-on administration and operational experience with ThreatConnect (or similar Threat Intelligence Platforms), including platform configuration, workflow development, feed management, integrations, and reporting.
  • Experience integrating ThreatConnect with SIEM, SOAR, incident response, ticketing, and vulnerability management tools.
  • Strong understanding of cyber threat intelligence methodologies, threat actor tracking, IOC management, threat feed ingestion, and intelligence-sharing frameworks.
  • Experience working with technologies such as ThreatConnect, Splunk, Microsoft Sentinel, QRadar, ServiceNow, Swimlane, Palo Alto XSOAR, Qualys, Tenable, and Defender TVM.
  • Experience automating security workflows using Python, PowerShell, APIs, or similar technologies.
  • Strong knowledge of MITRE ATT&CK, NIST CSF, OWASP Top 10, CVEs, and vulnerability risk management best practices.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.collegerecruiter.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

26:47 min

Exploring pathways to application security careers and research workflows

Vandana Verma Sehgal · LIVE

2:38 min

Establishing comprehensive monitoring and log management

Michael Eder +1 · LIVE

1:23 min

Understanding the complexity of cybersecurity domains

Jennifer Reif · LIVE

3:10 min

Correlating dispersed logs using structured request tracing

Michael Eder +1 · LIVE

4:19 min

Introduction to network security and endpoint monitoring architectures

Christoph Ruggenthaler · LIVE

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · World Congress 2022

Videos

See all

Related articles

See all